Query limitshard5-8 years

A GraphQL API has a depth limit of ten levels in production. An attacker sends `orders(first: 1000000) { id }` — one field, one level deep. Does the depth limit stop it, and if not, what does?

The depth limit doesn't even see this query as a problem — it's one level deep, well under ten, and depth limiting only counts nesting, never list sizes. orders(first: 1000000) { id } asks the database for a million rows through a single, shallow field, which is exactly the shape depth limiting was never built to catch: the lesson's own framing is that depth stops a query that's deep, not one that's wide. What stops it is complexity limiting, which walks the same selection tree but multiplies a per-field cost through every list argument it passes under — a first: 1000000 list field costs roughly a million times whatever's selected inside it, so the cost formula picks up exactly the number the client controls and rejects the query before a single resolver runs.

The lesson behind it →